Internal Audit explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Subsection 5605 permits internal audit services only where the client designates a competent resource reporting to those charged with governance and retains five responsibilities; Subsection 5606 applies a parallel four-condition test to IT systems services and lists what amounts to assuming management responsibility.
Subsection 5605 — what internal audit services cover
Paragraph 5605.2 A1 describes internal audit services as a broad range of activities that might involve assisting the client in performing one or more aspects of its internal audit activities, including:
- monitoring of internal control — reviewing controls, monitoring their operation and recommending improvements;
- examining financial and operating information relevant to sustainability, by reviewing the means used to identify, measure, classify and report it and by inquiring into individual items including detailed testing of transactions, balances and procedures;
- reviewing the economy, efficiency and effectiveness of operating activities relevant to sustainability, including non-financial activities; and
- reviewing compliance with laws, regulations and other external requirements, and with management policies, directives and other internal requirements.
Paragraph 5605.2 A2 notes that scope and objectives vary widely with the entity's size and structure and the needs of those charged with governance and management, and might involve matters that are operational in nature which will be considered in the assurance of sustainability information.
The five client responsibilities
Paragraph R5605.3 recalls that R5400.20 precludes assuming a management responsibility, and requires the firm to be satisfied of five things:
| Clause | The client must |
|---|---|
| (a) | Designate an appropriate and competent resource, who reports to those charged with governance, to (i) be responsible at all times for internal audit activities, and (ii) acknowledge responsibility for designing, implementing, monitoring and maintaining internal control |
| (b) | Review, assess and approve the scope, risk and frequency of the internal audit services |
| (c) | Evaluate the adequacy of the services and the findings resulting from them |
| (d) | Evaluate and determine which recommendations to implement, and manage the implementation process |
| (e) | Report to those charged with governance the significant findings and recommendations |
Clause (a) of R5605.3 carries two requirements that firms often satisfy only partly. The resource must be appropriate and competent — a nominal appointee does not meet it — and must report to those charged with governance, not to the finance function or to whoever commissioned the work.
Note also what that person must acknowledge: responsibility for designing, implementing, monitoring and maintaining internal control. That is much wider than responsibility for the internal audit engagement. And clause (e) closes the loop by requiring the client, not the firm, to report significant findings upward. A firm that presents its own findings directly to the audit committee has taken over the last of the five responsibilities.
Paragraph R5605.6: a firm or network firm shall not provide internal audit services to a sustainability assurance client that is a public interest entity if the provision might create a self-review threat.
Subsection 5605 runs from R5605.3 directly to R5605.6. There is no 5605.4 and no 5605.5 in the printed text. This matches the pattern recorded elsewhere in Part 5, where subsection paragraph numbers are aligned with the corresponding section in Part 4A and paragraphs without a sustainability counterpart are omitted. Cite by the numbers printed and do not infer a missing requirement.
Subsection 5606 — IT systems services
Paragraph 5606.2 A1 lists the services: designing or developing hardware or software IT systems; implementing them, including installation, configuration, interfacing, or customization; operating, maintaining, monitoring, updating or upgrading them; and collecting or storing data or managing (directly or indirectly) the hosting of data.
Paragraph 5606.2 A2 explains why they matter: the systems might aggregate source data, form part of the internal control over sustainability reporting, or generate information that affects the sustainability information records or reported information including disclosures — though they might equally involve matters unrelated to any of that.
Paragraph R5606.3 imposes four conditions, parallel to R5605.3. The firm must be satisfied that the client:
- (a) acknowledges its responsibility for establishing and monitoring a system of internal controls;
- (b) through a competent individual, preferably within senior management, makes all management decisions on the design, development, implementation, operation, maintenance, monitoring, updating or upgrading of the systems;
- (c) evaluates the adequacy and results of that work; and
- (d) is responsible for operating the IT system and for the data it generates and uses.
What amounts to taking over management
Paragraph 5606.3 A1 gives concrete examples of IT arrangements that result in the assumption of a management responsibility:
- storing data or managing (directly or indirectly) the hosting of data on the client's behalf — including acting as the only access to a financial or non-financial information system; taking custody of or storing the client's data or records such that the client's own data or records are otherwise incomplete; and providing electronic security or back-up services, such as business continuity or a disaster recovery function; and
- operating, maintaining, or monitoring the client's IT systems, network or website.
Paragraph 5606.3 A2 draws the line on the other side: the collection, receipt, transmission and retention of data provided by the client in the course of the assurance engagement, or to enable a permissible service, does not result in assuming a management responsibility.
The examples in 5606.3 A1 are unusually specific, and they cover services a firm may not think of as IT systems work at all. Disaster recovery and business continuity provision are named. So is taking custody of records such that the client's own records are incomplete — a description that fits many document management and data room arrangements. So is being the only access to a client information system.
Each of those is an assumption of management responsibility, which R5400.20 prohibits outright for every client, public interest entity or not. That is a stronger consequence than a self-review threat, and no safeguard reaches it. A firm offering a technology platform to an assurance client should check where the data physically sits and whether the client could operate without the firm.
Paragraph 5606.4 A3 gives examples of IT services that create a self-review threat where they form part of or affect the client's records or internal control over sustainability reporting: designing, developing, implementing, operating, maintaining, monitoring, updating or upgrading IT systems, including those related to cybersecurity; supporting the client's IT systems, including network and software applications; and implementing sustainability information management systems or sustainability reporting software, whether or not developed by the firm.
Paragraph R5606.6 prohibits IT systems services for a public interest entity where the provision might create a self-review threat. For other clients, 5606.5 A1 offers one safeguard — professionals who are not assurance team members.
The last example in 5606.4 A3 says whether or not it was developed by the firm or a network firm. So implementing a vendor's sustainability reporting platform for an assurance client creates a self-review threat on the same footing as implementing the firm's own product — and for a public interest entity client, R5606.6 then prohibits it. The threat comes from the firm's involvement in the system that produces the information it will assure, not from authorship of the software.
Practical checklist
- For internal audit services, confirm all five R5605.3 responsibilities sit with the client.
- Check the designated resource is competent and reports to those charged with governance.
- Let the client report significant findings upward, not the firm.
- For a public interest entity, apply R5605.6 and R5606.6 — both keyed to a possible self-review threat.
- Test every IT engagement against the four conditions in R5606.3.
- Screen for the named management responsibility arrangements — hosting, sole access, incomplete client records, back-up and disaster recovery.
- Treat data received for the engagement as outside that, per 5606.3 A2.
- Treat implementing third-party reporting software as within the self-review analysis.
Common mistakes
- Appointing a nominal internal audit resource who reports to management.
- Presenting internal audit findings to the audit committee on the client's behalf.
- Treating hosting or back-up as a technical service rather than a management responsibility.
- Holding client records such that the client's own set is incomplete.
- Assuming vendor software implementation is outside the subsection.
- Looking for a safeguard against an assumption of management responsibility.
Key Facts About Internal Audit
- Applies in: All states across India, under the relevant central law.
- Mode: Mostly online via the official government portal.
- Typical timeline: Ranges from a few days to a few weeks depending on the case.
- Non-compliance: May attract penalties, interest or late fees.
- Expert help: TaxClue completes the entire process end to end for you.
What are internal audit services?
Paragraph 5605.2 A1 lists monitoring of internal control; examining financial and operating information relevant to sustainability; reviewing the economy, efficiency and effectiveness of operating activities relevant to sustainability; and reviewing compliance with laws, regulations and management policies.
What five things must the client do?
Under R5605.3 — designate an appropriate and competent resource reporting to those charged with governance who is responsible at all times for internal audit activities and acknowledges responsibility for internal control; review, assess and approve the scope, risk and frequency of the services; evaluate their adequacy and findings; evaluate and determine which recommendations to implement and manage implementation; and report significant findings and recommendations to those charged with governance.
Over 90% of compliance penalties in India arise from missed due dates — timely handling can save businesses thousands of rupees each year.
Internal Audit: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.